# CVE-2025-36002

## Summary

- **CVE ID:** CVE-2025-36002
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-260
- **Published:** Oct 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.

## Affected Products

- IBM — Sterling B2B Integrator (6.2.0.0)
- IBM — Sterling B2B Integrator (6.2.1.0)
- IBM — Sterling File Gateway (6.2.0.0)
- IBM — Sterling File Gateway (6.2.1.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7248129)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._